There are two great analysis of the same piece of improved rootkit malware,
Hiding the Unseen at
F-Secure's Blog and
Raising the Bar: Rustock.A and Advances in Rootkits at
Symantec's BlogAnother interesting recent discussion on improved rootkits from Joanna Rutkowska. I can't wait for her to release this. The comparison to SubVirt is key.
BluePill on InvisibleThings-toby